Squid Out-of-bounds Read Vulnerability - CVE-2026-47729
Squid is a caching proxy for the Web. Prior to 7.6 due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc) Squid is vulnerable to an out-of-bounds read: when a listing entry date in the TypeA or TypeB directory-listing formats is not followed by a filename parsing was not restricted to the input buffer so a trusted client accessing a misbehaving FTP server through Squid39s gateway feature could read memory from random unrelated transactions. This issue is fixed in version 7.6.